Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Druid — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Apache Druid, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security weaknesses associated with the Apache Druid data processing system. It specifically targets the vulnerability landscape within this open-source distributed data store, categorizing issues by common weakness enumerations and specific product components. The content collects a wide array of vulnerability types, including authentication bypasses, remote code execution flaws, denial-of-service conditions, and information disclosure defects. These entries cover a broad historical time range, tracking security incidents from the earliest releases through recent updates. The data includes both critical severity ratings and lower-impact configuration errors that may lead to privilege escalation or data leakage. By consolidating these records, the page offers a centralized repository for understanding the evolving security posture of the software over time. Here, researchers and administrators can track a vendor's advisories as they are published and correlate them with upstream patches. Users can also gain a deeper understanding of a weakness class by observing how it manifests across different versions of the platform. Furthermore, the database allows for a detailed look-up of a product's vulnerability history, enabling teams to assess risk based on past exploits and remediation timelines. This structured approach supports informed decision-making for patch management and infrastructure hardening, ensuring that security teams have the necessary context to prioritize remediation efforts effectively without relying on fragmented sources.

Vendor: Apache

CVE ID Title CVSS Severity Published
CVE-2026-23906 Apache Druid: Authentication Bypass via LDAP Anonymous Bind CWE-287 9.8AI Critical AI 2026-02-10
CVE-2025-59390 Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly. CWE-338 9.8AI Critical AI 2025-11-26
CVE-2025-27888 Apache Druid: Server-Side Request Forgery and Cross-Site Scripting CWE-918 5.4 - 2025-03-20
CVE-2024-45537 Apache Druid: Users can provide MySQL JDBC properties not on allow list CWE-20 6.5 - 2024-09-17
CVE-2024-45384 Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack 7.5 - 2024-09-17
CVE-2022-28889 Clickjacking in the web console CWE-1021 4.3 - 2022-07-07
CVE-2021-44791 Reflected XSS on certain HTTP endpoints CWE-79 6.1 - 2022-07-07
CVE-2021-36749 Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920) 6.5 - 2021-09-24
CVE-2021-26920 Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended 6.5 - 2021-07-02
CVE-2021-26919 Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems. 8.8 - 2021-03-30
CVE-2021-25646 Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. 8.8 - 2021-01-29
CVE-2020-1958 Apache Druid 注入漏洞 6.5 - 2020-04-01

All 12 known CVE vulnerabilities affecting Apache Druid with full Chinese analysis, references, and POCs where available.